The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact the availability of the application.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655 | vendor advisory |
https://launchpad.support.sap.com/#/notes/3012021 | permissions required vendor advisory |